Wednesday, December 10, 2014

ICS-CERT Updates Their Alert on Ongoing Malware Campaign

Today the DHS ICS-CERT published the second update of their alert concerning the BlackEnergy malware campaign. The first update was published on October 29th and the original alert was published the day before.

This update provides a little more information on the probable existence of a Siemens WinCC attack vector involved in the campaign. The original alert only provided the vaguest hint about the use of WinCC which ICS-CERT plainly said they could not confirm. They now say:

“While ICS-CERT lacks definitive information on how WinCC systems are being compromised by BlackEnergy, there are indications that one of the vulnerabilities fixed with the latest update for SIMATIC WinCC [link added] may have been exploited by the BlackEnergy malware. ICS-CERT strongly encourages users of WinCC, TIA Portal, and PCS7 to update their software to the most recent version as soon as possible.”

This version of the alert also updates the Yara Rules that allow organizations to interpret the results of scan conducted with the Yara pattern matching tool. ICS-CERT recommends that organizations running the updated scan and the application of the updated Yara Rules send copies of the results to ICS-CERT for more detailed interpretation of the data if there are any indications of potential compromise in the results.


ICS-CERT does not specifically state in this update that even those organizations that have already run the earlier version should run the updated scan. Since this apparently checks for later versions (or at least different versions) of the malware associated with BlackEnergy, it would seem to me that it would only be prudent to run this latest version and any new versions that ICS-CERT might publish in the future.

Hazardous Materials Information Advisory Committee

With just days left in the 113th Congress 18 bills were introduced in the House and Senate yesterday. One of those is of potential specific interest to readers of this blog:

H.R.5822 : To establish a Hazardous Materials Information Advisory Committee to develop standards for the use of electronic shipping papers for the transportation of hazardous materials, and for other purposes. Sponsor: Rep Lipinski, Daniel (D,IL)


The chances of this coming to the floor in both the House and Senate before this Congress adjourns for the last time are slim to none.

Tuesday, December 9, 2014

Rules Committee Hearing on FY 2015 Spending Bill

Late this evening the House Rules Committee announced that they would conduct a hearing on HR 83. That bill had passed in the House and then in the Senate with amendments. The hearing tomorrow will introduce substitute language that will turn the bill into the Consolidated and Further Continuing Appropriations Act, 2015.

The bill will provide funding for the bulk of the Federal Government through September 30th, 2015. DHS is dealt with in Title L of the bill; providing spending authority for that department only through February 27th. The CFATS program is never specifically mentioned in Title L, but the way that Title is written will extend the current CFATS authorization (which currently expires on Thursday night) through the same date.


This bill will come to a floor vote in the House on Thursday and possibly the same day in the Senate. I expect that we may see a short (2 to 4 day) continuing resolution come to the floor in the House tomorrow to avoid a chance of an inadvertent shutdown of the federal government Thursday at midnight.

ICS-CERT Publishes OpenSSL Update and 2 New (Almost) Advisories

The afternoon the DHS ICS-CERT updated (up to ‘F’ now) their Situational Awareness Alert for the OpenSSL vulnerability. They also published new advisories for vulnerabilities in systems from Trihedral Engineering and Yokogawa.

HeartBleed

This update adds ABB to the list of vendors with affected products. The Relion 650 series has a patch available to mitigate the vulnerability. There is no explanation as to why this update was so long in coming. The last HeartBleed update was published back in April and ABB published their advisory in July.

Trihedral Advisory

This advisory describes an integer overflow vulnerability in their VTS and VTScada products. The vulnerability was reported by an anonymous researcher through ZDI. ICS-CERT reports that Trihedral has produced a patch that mitigates the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to cause the application to crash.

Interestingly the Trihedral update page says nothing about this vulnerability in their upgrade descriptions. ZDI does report that they notified Trihedral of this vulnerability (ZDI-CAN-2599) on November 19th so this was a very quick response.

Yokogawa Advisory

This advisory reports an XML external entity processing vulnerability in the Yokogawa FAST/TOOLS application. The vulnerability was reported by Timur Yunusov, Alexey Osipov, and Ilya Karpov of Positive Technologies Inc. ICS-CERT reports that Yokogawa has developed a service pack that mitigates this vulnerability, but no mention is made that the researchers have verified the efficacy of the fix.

ICS-CERT reports that it would be difficult to craft an exploit of this vulnerability and local access would be required. Yokogawa also reports (in their CVSS calculation) that local access is required, but note that it can be exploited by an attacker that “intrudes into the WebHMI server in any way”. Something may be lost in translation there because that sounds to me like remote access could be used to exploit this vulnerability.


I mentioned earlier that Yokogawa had publicly reported this vulnerability over a week and a half ago; not very timely reporting by ICS-CERT.

Monday, December 8, 2014

If Sony Had Been a Chemical Plant

The infosec world is still buzzing about the recent hack of Sony and how completely their information systems were owned by the attacker. Researchers will be pouring over this attack for a while trying to figure out how it all happened and what could have been done to prevent it.

The Hack

The Sony hackers took, among other things, valuable intellectual property (high quality digital copies of yet to be released films), thousands of internal documents (one source said 1 terabytes worth), and system access information to include log-in credentials and passwords. The attack was so thorough that Sony was forced to shut down all computer systems for days while they went through and inspected/cleaned every machine.

The TWITERVERSE is all agog, of course about #SonyHack. I’ve made my own small contribution (sans hashtag, of course). The one tweet of mine that I would like to look at in more detail came on Saturday:

I guess we should be glad that Sony didn't make dangerous chemicals or supply something really important....”

XYZ Chemical Company

So what would have been different if it had been XYZ Chemical Company that had attracted the ire of the GOP attackers? Other than differences in what IP was stolen, probably not much in the immediate results of the attack. The longer term results could have been much more serious to communities around XYZ plants and possibly to the nation.

Intellectual property theft? Well, formulations come to mind first. The wholesale release of formulations would give every competitor here and around the world a leg up in understanding how XYZ makes their products. Even for fully mature product lines, the little tweaks to the formulation a company makes can make a major difference in pricing and performance. This could make for a serious change in competitive status.

The public publishing of the formulations could have other consequences as well. There are a number of chemicals being used in the chemical industry that have raised concerns among environmental activists. If a formulation list included such chemicals the company could come under additional scrutiny from these activists, potentially leading to image issues. Worse yet, if any of the chemicals being used were on the lists of chemicals offensive to various environmental wacko fringe groups, the facility could become a target for varying degrees of physical attacks.

Control System Insecurity

From a security perspective the IP that is of more concern, however, would be process flow diagrams and control system working documents. Those pieces of information would make it much easier for an attacker that has gained access to the control system to figure out how to manipulate the controls in that system in a manner that could disrupt the facility in the worst possible way.

Since most corporate types use a single set of login credentials across the entire spectrum of company computer systems, it is very likely that even if the control systems were not directly breached in the attack, there would be useable log-in credentials for the control systems to be culled from the corporate log-ins. Once an attacker can gain legitimate access to a control system, the various ‘insecure-by-design’ problems become very large vulnerabilities.

If the control system had been directly breached as well the problems become much worse. The shut down and start-up of a chemical control system, particularly with continuous chemical processes like refineries, is not something that is done lightly or quickly. And searching control systems for logic bombs, back-doors, and forms of re-programing is a much more time consuming task than for an IT system of comparable size. The larger the number of PLCs involved the more difficult the task becomes.

Physical Insecurity

One set of computer data files that no one wants to see released are physical security plan files. Password and log-in credentials can be changed fairly easily, but making significant changes to a site security plan are very expensive and time consuming. The public availability of site security plans would make the facility much more susceptible to physical attack or theft of chemicals.

While there are some people that claim that the Sony attackers had at least some physical access to the corporate computer system that would not necessarily mean that that access included detailed information about the site security plan. Most folks entering a facility are aware of only a small part of the over-all security plan for the facility.

For many chemical manufacturing facilities a major source of security concerns can be found in the computer systems of the order handling folks. The timing and sourcing of inbound and outbound chemical shipments makes them that much more vulnerable to off-site attack. Those attacks may allow for inbound shipments to be intercepted and converted to a method of attack (VBIED) or simply diverted to some other nefarious or illegal end.

The Big Picture


The major take away from this attack is that this was no longer a hack to deface a web site, steal money or credentials. This was a full scale attack on a company with the intent of seriously harming the company for some as of yet unknown reason. The scope and scale of the attack is unlike anything we have seen in the corporate world. Unfortunately, as with all things cyber, it will undoubtedly set the new gold standard for serious attacks as it give other groups and hackers ideas about what can be accomplished with a successful cyber attack.

Sunday, December 7, 2014

Interesting ICS Advisory Released on US-CERT Secure Portal

It has come to my attention that ICS-CERT has released an interesting advisory on the US-CERT Secure Portal. The advisory reportedly deals with an industrial control system and it currently looks like the vendor is not intending to fix the vulnerability. I have not seen the advisory as I don’t have access to the Secure Portal (I was offered, but declined so I could report on things like this), but it seems odd that this vendor is not cooperating with ICS-CERT.

Just another good reason for control system owners to seek access to US-CERT Secure Portal.

Friday, December 5, 2014

Bills Introduced – 12-04-14

Yesterday, nearing the end of the second week of the lame duck Congress 29 bills were introduced. A trio of software security bills were introduced:

HR 5793 : To ensure the integrity of any software, firmware, or product developed for or purchased by the United States Government that uses a third party or open source component, and for other purposes. Sponsor: Rep Royce, Edward R. (R,CA)

HR 5800 : To prohibit Federal agencies from mandating the deployment of vulnerabilities in data security technologies. Sponsor: Rep Lofgren, Zoe (D,CA)

S.2981 : A bill to prohibit Federal agencies from mandating the deployment of vulnerabilities in data security technologies. Sponsor: Sen Wyden, Ron (D,OR)


According to a press release from the Wyden office, his bill is designed to stop Federal government agencies from requiring the existence of backdoors in US software or electronic devices. A copy of the bill language available on the Wyden web site contains an interesting loop hole; it only applies to “any computer hardware, computer software, or electronic device that is made available to the general public [emphasis added]” {§2(c)(2)}. A large truck could be driven through that loop hole.
 
/* Use this with templates/template-twocol.html */